CVE-2025-3110: Medium severity OpenVPN OpenVPN Access Server vulnerability
Published Jul 8, 2026
·Updated
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
Affected Software
2 affected components
OpenVPN OpenVPN Access Server>=2.7.2<=3.1.0
OpenVPN OpenVPN Access Server>=2.7.2<=3.1.0
Event History
Jul 8, 2026
CVE Published
via MITRE·04:19 PM
Data Sourced
via MITRE·04:19 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3110?
The severity of CVE-2025-3110 is medium with a CVSS score of 6.9.
2
How do I fix CVE-2025-3110?
To fix CVE-2025-3110, upgrade OpenVPN Access Server to version 3.1.1 or later.
3
What are the implications of CVE-2025-3110?
CVE-2025-3110 allows remote attackers to perform HTTP request smuggling attacks when OpenVPN Access Server is configured behind a reverse proxy.
4
Which versions are affected by CVE-2025-3110?
CVE-2025-3110 affects OpenVPN Access Server versions 2.7.2 through 3.1.0.
5
What kind of attacks can be performed using CVE-2025-3110?
Attackers can exploit CVE-2025-3110 to conduct HTTP request smuggling attacks.